How to check a link before opening it

A safe link is one that takes you where it says it will, without installing malware, stealing your password, or redirecting you to a fake login page. You can check most links in three ways before clicking: hover over the link to see the real destination, use a link scanner, or examine the URL itself for red flags.

The fastest method is to hover your mouse over the link without clicking. In most browsers and email programs, a small box appears showing the actual web address the link points to. If the address doesn't match what the link text says, or if it looks suspicious, don't click it. This works in Gmail, Outlook, Firefox, Chrome, Safari, and Edge.

If you've already clicked and the page looks wrong — asking for your password when you didn't expect it, showing a login screen that looks slightly off, or displaying urgent warnings — close the tab when ready without entering any information. These are common signs of a phishing page designed to steal credentials.

Key Takeaways

  • Hover over any link to see its real destination before clicking, which takes one second and catches most phishing attempts.
  • Phishing pages often misspell the real domain slightly (like "amaz0n.com" instead of "amazon.com") or use a completely different domain with familiar words in the path.
  • Legitimate companies never ask you to verify your password by clicking a link in an email — that is always a phishing attempt.
  • Link scanners like VirusTotal and URLhaus check whether a URL is known to be malicious, but they cannot catch brand-new attacks.
  • Shortened links (bit.ly, tinyurl) hide the real destination, so avoid clicking them unless you trust the person who sent them.

What to look for in a suspicious URL

The domain name — the part after "https://" and before the first single slash — is what matters most. Attackers often use domains that look similar to legitimate ones. "Amaz0n.com" (with a zero instead of the letter O) or "paypa1.com" (with the number 1 instead of the letter L) are examples. Read the domain character by character, not as a whole word.

Another common trick is to put the real company name in the path instead of the domain. A link like "https://find-paypal-verify.com/paypal/login" looks like it goes to PayPal, but the actual domain is "find-paypal-verify.com," which is not PayPal. The part after the domain name is just a folder path and means nothing about where you actually are.

Legitimate URLs from major companies are usually short and straightforward: amazon.com, gmail.com, chase.com. If a link is long, has many hyphens, includes random numbers, or looks cluttered, it is more likely to be suspicious. This is not a perfect rule — some real sites have complex URLs — but combined with other signs it is worth noting.

Using online link scanners

A link scanner is a free website that checks whether a URL is known to be malicious. The most widely used are VirusTotal (virustotal.com) and URLhaus (urlhaus.abuse.ch). You paste the suspicious link into the scanner, and it tells you whether antivirus companies or security researchers have flagged it.

To use VirusTotal, go to virustotal.com, click the "URL" tab, paste the link you want to check, and press Enter. The page shows you results from dozens of security vendors. If most say "clean" or "undetected," the link is probably safe. If several flag it as malicious, do not click it.

Keep in mind that scanners only catch links that are already known to be bad. A brand-new phishing page created yesterday may not show up as malicious yet. Scanners are useful as a second opinion, but they are not foolproof. The hover-and-read method is still your first line of defense.

Why shortened links are riskier

Services like bit.ly, tinyurl, and short.link compress long URLs into short ones. The problem is that you cannot see where the link actually goes until you click it. An attacker can create a shortened link that looks innocent but points to a phishing page or malware site.

If someone sends you a shortened link in an email or message, especially if it is unexpected, treat it with extra caution. Hover over it if you can (though some shortened links don't show a preview), or paste it into a link scanner before clicking. If you do not recognize the sender or the context seems odd, it is safer to skip it entirely.

Shortened links are common in legitimate contexts — social media posts, newsletters, text messages — so they are not automatically dangerous. But they do hide information, which is why attackers like them. When in doubt, ask the sender what the link goes to before clicking.

Phishing emails and fake login pages

A phishing email is a message designed to trick you into clicking a malicious link or entering your password on a fake website. These emails often claim there is a problem with your account, ask you to confirm your identity, or warn you of suspicious activity. The sender address may look official, but the links inside point to fake login pages.

Real companies — your bank, PayPal, Amazon, your email provider — never ask you to verify your password by clicking a link in an email. If you receive an email asking you to do this, it is phishing. Delete it. If you are worried about your account, go directly to the company's website by typing the address yourself in the browser, rather than clicking any link in the email.

Fake login pages look nearly identical to the real ones. They may have the correct logo, colors, and layout. The only way to catch them is to check the URL before entering anything. If the domain is wrong, or if you arrived there by clicking a link in an unexpected email, close the page and do not enter your password.

Safe habits when you are unsure

If a link looks suspicious but you need to know where it goes, use a scanner or ask the sender directly. Do not click it out of curiosity. If an email asks you to click a link to verify your password, account, or payment information, assume it is phishing and contact the company through their official website or phone number instead.

Bookmark the websites you visit regularly — your email, banking, shopping, social media — so you can go directly to them without relying on links. This eliminates the risk of clicking a malicious link that looks like it goes to a familiar site.

Keep your browser and operating system updated. Modern browsers warn you when you are about to visit a known malicious site, but only if the software is current. Updates also patch security holes that attackers exploit.

Frequently Asked Questions

What does it mean if a link has "https" instead of "http"?

The "s" means the connection is encrypted, which is good for security. However, phishing pages can also use "https," so it is not a sign that a link is safe. Always check the domain name itself, not just whether the connection is encrypted.

Can I get malware just by hovering over a link?

No. Hovering does not execute anything — it only shows you a preview of the URL. You have to actually click the link for anything to happen. Hovering is completely safe.

Is a link safe if it comes from someone I know?

Not necessarily. Attackers sometimes hack email accounts or social media profiles and send malicious links to all the contacts. If a link from a friend looks suspicious or unexpected, ask them about it through another method before clicking.

What should I do if I already clicked a suspicious link?

If the page loaded but you did not enter any information, you are probably fine — close the tab. If you entered your password or payment information, change your password when ready and contact the company to report the phishing attempt. If your device starts acting strangely afterward, run a malware scan with your antivirus software.

Do I need special software to check if a link is safe?

No. Hovering over links works in every browser and email program. Link scanners like VirusTotal are free websites you can access from any browser. You do not need to install anything.